At a glance
- ASN
- AS13335
- Organization
- Cloudflare
- Category
- Cloud & CDN
- Region
- Global
Use AS13335 as a routing anchor when investigating traceroutes, hosting ownership, or provider reputation. ASN pages work best when combined with live IP checks.
Anycast-heavy CDN and security network frequently seen in DNS and HTTP. For practical diagnostics, AS13335 should be read as Cloudflare's cloud & cdn footprint in Global, not as a complete explanation by itself. The value of the ASN is that it gives you the routing organization currently associated with the IP path, which is the first stable clue before you inspect hostnames, registration records, and reputation data.
A lookup that returns AS13335 tells you that the address is being announced through a routing domain operated by Cloudflare. That is different from proving who controls the device, account, website, or application behind the traffic. Large networks delegate ranges, operate different service families, peer in several markets, and sometimes carry customer traffic that only becomes clear after reverse DNS or WHOIS / RDAP inspection.
This page is written as an interpretation layer for Cloudflare, not as a raw ASN database row. Use it when you need to decide whether an IP looks like ordinary cloud & cdn traffic, infrastructure traffic, transit, mobile egress, or a possible proxy/VPN path. The safest workflow is to start with the ASN, confirm ownership, then compare the result with DNS, hostname, geolocation, and blacklist signals.
Cloud and CDN ASNs usually point to infrastructure rather than a normal household ISP. The same ASN can host customer applications, API traffic, caches, DNS edges, security gateways, and automated systems, so the ASN alone should not be treated as the final owner of the workload.
For AS13335, the category label is Cloud & CDN. That category should shape your expectations before you act on the result. A cloud ASN, a backbone ASN, a residential ISP ASN, and a mobile ASN all answer different questions. The provider name may be accurate in all four cases, but the conclusion you draw from it should be completely different.
The most common mistake is reading a cloud ASN as proof that the platform itself caused the traffic. In practice, the address may belong to a customer VM, a managed service, a CDN edge, a security product, or an internal provider system.
In day-to-day use, Cloudflare should be compared with the surrounding evidence. If reverse DNS, WHOIS ownership, IP geolocation, and blacklist status all tell the same story, confidence goes up. If those signals disagree, the ASN is still useful, but it should be treated as the routing clue rather than the final answer.
For cloud and CDN traffic, reverse DNS, HTTP headers, TLS certificates, and WHOIS or RDAP contact data usually matter more than the organization name alone. The ASN gives you the platform boundary; the other signals tell you which service layer you are looking at.
Start with the visible IP, map it to AS13335, then check whether the organization, region, and category make sense together. If the IP claims to be in one country while Cloudflare's routing context points somewhere else, do not assume the lookup is broken. That mismatch can come from data-center placement, mobile gateways, backbone POPs, recent reassignment, or a stale geolocation database.
Next, inspect reverse DNS. A descriptive PTR can expose a city code, broadband pool, cloud region, CDN edge, business circuit, or transit router. A generic PTR does not invalidate the ASN result, but it does mean you should lean harder on WHOIS / RDAP and live reputation checks. For mail, abuse, and account-security decisions, add blacklist history before making a block or escalation decision.
Finally, compare AS13335 with related provider pages and educational material. If Cloudflare behaves like a normal access provider, ISP context may be enough. If it behaves like transit or cloud infrastructure, the downstream customer or service layer matters more than the headline organization name.
Abuse and reputation workflows should separate platform reputation from customer reputation. A bad request from a cloud ASN does not automatically mean the entire platform is risky, but it does justify checking hosting fingerprints, proxy classifications, and blacklist history.
For allowlists, blocklists, fraud rules, or abuse reports, avoid using AS13335 as a single yes-or-no signal. ASN-level decisions have a large blast radius. A full provider range can include normal users, enterprise customers, infrastructure services, shared gateways, and temporary traffic patterns that do not deserve the same treatment.
A better pattern is to score AS13335 together with IP reputation, recent behavior, hostname evidence, account history, TLS or HTTP fingerprints, and the sensitivity of the action being protected. That approach keeps Cloudflare useful as context without turning one routing label into an overbroad enforcement rule.
For ordinary users, the practical takeaway is simpler: if your IP lookup shows AS13335, it means your traffic is associated with Cloudflare's network path. It does not automatically reveal your exact location, identity, or device. To test whether a VPN, proxy, or network change altered the path, compare the ASN before and after the change and then run DNS and WebRTC leak checks if privacy matters.
Browse the full ASN directory for additional cloud, ISP, and backbone networks, use ASN Lookup if you want to map a live IP to its ASN, or read what ASN means if you need the networking basics first.
IP ranges are announced through BGP by autonomous systems like AS13335. When you resolve an IP to ASN, you identify the network currently advertising that route.